Runtime protection for everything
your code touches. One brain.
Shield learns how each of your apps, APIs and LLMs actually behaves — a positive-security baseline learned per tenant, not a global model — then blocks the deviations a signature WAF can't see. It covers the app, API, LLM, network/DNS and cloud layers, and fuses all of it (plus your endpoints) into one correlated view. It proves what it blocks. It does not claim to prevent every zero-day, and it is not a rip-and-replace of your CDN.
How a request becomes a verdict
Runtime traffic passes through three engines that each learn a per-tenant baseline of normal. What matches the baseline reaches your assets; what deviates is blocked with proof and queued for review. Every signal feeds one correlation brain, so an attacker seen across app, DNS and cloud becomes a single incident.
Four engines, one correlation brain.
Each engine is useful on its own. Connect a second and the brain starts correlating across them — the same source hitting your app, your DNS and your cloud becomes one incident instead of three disconnected alerts.
- Sentinel — application shield.A one-line SDK learns each web app, API and LLM's normal request/response behavior, then blocks logic abuse, broken-auth flows and the exploitation of vulnerable code paths. Every block comes with proof, reviewed in a per-tenant approve/deny queue so false positives don't drown you.
- LLM Guard.Learns each model's approved prompts, tools and output shapes, then blocks prompt injection, unauthorized tool calls and sensitive-data egress at the boundary — seeded by the Nemesis Red OWASP-LLM corpus.
- Grid — telemetry & correlation. Connect cloud, SIEM, identity, firewall and the Nemesis engines. Grid reduces the volume before you pay to store it, and correlates everything through a unified entity graph. It is priced to sit in front of a SIEM, not to bill you by the gigabyte.
- Edge — network & DNS. Protective DNS and an optional inline proxy, backed by a per-tenant DNS model that flags the beaconing and tunneling a global blocklist misses. It deploys in front of any infrastructure or on top of your existing CDN.
Why this, when RASP mostly failed and WAFs miss?
Because the differentiator is per-tenant, not another global signature set. Miggo and Oligo do behavioral app defense; Infoblox and Palo Alto do behavioral DNS — all on models trained across every customer. Shield learns your normal, so a request that looks fine globally but abnormal for your app is caught, and a domain that looks benign globally but never resolved for you before is flagged.
- Prove, don't just detect.Every block ships with the captured evidence and the learned-vs-observed diff. No alert you can't action.
- Safe by default.Every app starts in observe mode. It watches and learns before it ever blocks, and you flip to enforce when the baseline is ready — the review queue is where you approve what's normal.
- One line, no source code. The SDK streams behavioral state, never your source. Node, Python, Go, Java, .NET.
- Self-serve, mid-market priced. The unified SecOps stack that used to take four six-figure tools and a SOC to assemble — Miggo/Oligo for app, Splunk/CrowdStrike for SIEM/EDR, Cloudflare for edge, Vanta for compliance — one platform, one price, correlated.
Compliance that pays for itself.
Because Shield is already the tool protecting you, the evidence comes from the live security data it runs — not a separate questionnaire product. Pick the frameworks that fit your sector and the countries you operate in, and it maps controls, shows exactly where you're failing, and tells you the precise requirement to close.
- 26 built-in frameworks. SOC 2, ISO 27001, PCI-DSS, HIPAA, GDPR, NIST CSF, DORA, NIS2, LGPD, CCPA and more, recommended by sector × region.
- Custom frameworks.Add one we don't ship — a regional AML rule, an internal standard — with your own requirements, and Shield detects the matching controls from your telemetry.
- Requirement-level truth.Every requirement shows its exact text, mapped controls, evidence, owner, and — when failing — precisely what's needed to pass.
And the rest of the console.
- Threat map. Every attack against every component you protect, live, routed to the specific asset it targets.
- Threat hunting. Start from any entity — an IP, user, domain or file hash — and follow its trail across every layer, pivoting through the entity graph.
- Custom rules. Block or rate-limit by IP, country, velocity, path, header or payload, applied to any product.
- Reports & trust badges.Board-ready reports on a schedule, plus an embeddable “Protected by Nemesis” badge that verifies your posture publicly.
Where it fits: the whole engagement.
Red finds the weakness. Shield guards the app, API, network and cloud at runtime. Blue stops the payload on the device. One correlation brain over all three.
Pricing.
- Free1 app + protective DNS · learn-and-alert · metered$0
- Promultiple apps & domains · full enforce · behavioral network model$49 / mo
- Businessfleet · all connectors · full compliance suite · cross-layer correlation · SSO$599 / mo
- Enterprisededicated · advanced compliance · custom SLAcustom
- MSSPmulti-tenant · wholesale, metered · white-label badgescontact
What it stops.
To actually do damage, an exploit has to make your app do something it doesn't normally do — and that is the moment Shield is built to catch. The whole class of runtime attacks that show up as a behavioral deviation: business-logic and flow abuse, broken-auth and access-control bypasses, exploitation of a vulnerable code path (the N-day and zero-day exploit classes), prompt injection and tool abuse against your LLMs, and the DNS beaconing and tunneling a global blocklist never sees. Because the baseline is learned per tenant, Shield stops the request that looks fine to the rest of the internet but is abnormal for your app — the exact case a signature WAF waves through. Every block ships with proof.
The honest edge: an attack that stays entirely inside your learned envelope, or one accidentally learned as normal, won't be blocked on behavior alone. That is a narrow band, and it is why the per-tenant review queue keeps tightening the baseline and why Nemesis Redpressure-tests it from the outside. Edge is the security-intelligence layer in front of your infra or CDN, not a replacement for a global edge network's raw capacity. We publish every limit in full on the trust center.